3 ms·
Since it seems to have been glossed over in the court transcript, can anyone explain how exactly a VM or client for remote VM could be used to bypass the monito
by NotMichaelBay 1y ago
Since it seems to have been glossed over in the court transcript, can anyone explain how exactly a VM or client for remote VM could be used to bypass the monitoring?
Wouldn't the monitoring software capture any application's network activities, including a client for a Remote VM? I'm imagining something like Wireshark?
- nusl 1y agoA VM would bypass monitoring software installed on devices the person uses. A VPN would obscure their traffic such that it is encrypted and not easily monitored. Even something like SSH is encrypted and not straight-forward to monitor, so a VPN isn't required to do this anyway. A remote VM would combine both of these things, where the device/computer is in a location that isn't monitored and accessed by means aimed at bypassing controls in place. Activities carried out from the remote VM are then not monitored. User + Devices -> VPN/other -> Remote VM -> Unmonitored Activities / Network Access ^ Monitoring is here, but may not capture the rest of the chain Law enforcement would need to monitor the VM itself to monitor those activities, or I guess request logs from the provider if at all possible. There's a limit to how much you can monitor someone and I assume there's a degree of good faith in cooperation with these controls. Failure to comply, seemingly, has severe consequences.
- NotMichaelBay 1y agoOkay, that makes sense. But the monitoring software should capture the connection request to the VPN or Remote VM?
- Shocka1 1y agoYeah I've been reading the PDF and a lot of finely detailed technical info is missing, making it hard to piece together. If he had the remote VM up and running, there would have at least been one persistent connection.
- rnhmjoj 1y ago> A VM would bypass monitoring software installed on devices the person uses. Not really, no: a VM is just another userspace application and a monitoring software should be able to capture its traffic just fine. If he was also using a VPN, tor or conneting to a remote machine that's another story, but only saying he was using a VM doesn't really mean much.
- dns_snek 1y agoIt's possible to pass PCI devices directly to the VM at which point they don't exist as far as the host OS is concerned. You can pass an entire USB hub to the VM and anything plugged into it is invisible to the host OS (at least by default).
- rnhmjoj 1y agoOk, but you certainly need root privileges to do that, in that case you could bypass the monitoring software in many other ways.
- Almondsetat 1y agoMonitoring software installed at the OS level can monitor both traffic and what applications generate it. But if the traffic is coming from a VM, it can only do the former.